Incredible: While the Muller report was being released, Facebook updates an old press post titled “Keeping Passwords Secure” with the new disclosure that millions of Instagram account passwords were internally stored in readable plaintext.
Remember how FB stored tens of millions of user passwords unencrypted on their servers? They just updated the blog to say that "millions of Instagram users" also had their passwords stored unencrypted. They originally said "tens of thousands of IG users"
If you are on Instagram and haven't already changed your password, it is time. Facebook has updated its prior statement to say that "millions" of Instagram users were affected by the security incident, not "tens of thousands". ➤ #facebook
So kept passwords in plain text format since ❗️❗️2012 ❗️❗️() . But hey ... it's okay! We can trust them. They promise they did nothing shady with them. 😒
A key argument for PAKE is that people with the best intentions constantly screw up and store unhashed passwords on their systems. One solution is to keep passwords off those systems.
Facebook says “these passwords were never visible to anyone outside of Facebook and we have found no evidence to date that anyone internally abused or improperly accessed them.” They will notify hundreds of millions of affected users
"We estimate that we will notify hundreds of millions of Facebook Lite users, tens of millions of other Facebook users, and tens of thousands of Instagram users"
What an embarrassment for Facebook. Salted and hashed passwords have been the norm for a very long time now.